Information Security Analyst
2 days ago
Dover
Job Description About DHIN The Delaware Health Information Network (DHIN) is the nation’s first statewide health information exchange. Established by statute as a not-for-profit public instrumentality, DHIN’s statutory mission is to facilitate the design and implementation of an integrated, statewide health data system to support the information needs of consumers, health plans, policymakers, providers, purchasers, and researchers to improve the quality and efficiency of health care services in Delaware. DHIN thus serves as an aggregator of health data from disparate sources and provides services to make that data useful in a variety of settings and to a variety of users. DHIN has collected and aggregated clinical data since 2007, and additionally administers Delaware’s All Payer Claims Database, with claims data from 2013 forward. Participation in DHIN by the health care community of Delaware is nearly universal, with expansion beyond state borders now also established. Position Overview The Information Security Analyst will be an integral part of delivering DHIN’s services to the Delaware healthcare community and beyond. Specifically, this position will have a role in developing and implementing security measures to protect DHIN’s computer networks and systems. This position will also manage security incidents, vulnerability remediation and provide feedback into the Continuous Service Improvement process so that DHIN continues to improve in all aspects of securing the services offered by DHIN. DHIN continues to focus on implementing industry best practices as defined by the IT Infrastructure Library (ITIL). After joining DHIN, all staff are required to pass the ITIL v4 Foundations certification exam. This position is required to understand both the standard and DHIN specific ITIL v4 Information Security Management and Risk Management practices. In addition, DHIN dedicates itself to maintaining a high-level of security for all the organization’s data. DHIN will obtain and maintain HITRUST certification to demonstrate this dedication. This position will participate in that ongoing certification effort. While delivering services, all DHIN staff interact with Delaware healthcare community stakeholders. The successful candidate should be able to communicate concepts clearly, concisely, and professionally to a variety of audiences. DHIN’s main office is located in Dover, DE. While this position will have the flexibility to work remotely, some in-office work is required. Duties and Responsibilities • Develop and maintain in-depth knowledge of the HITRUST CSF, HIPAA/HITECH Privacy and Security Rules, and all other applicable laws, regulations, and contractual requirements affecting DHIN’s privacy and security practices., • Collaborate with Information Security Management and DHIN leadership to recommend policy updates that strengthen DHIN’s commitment to privacy and security., • Identify endpoint, system, and software vulnerabilities, risks, and threats; recommend and implement remediation actions., • Monitor, triage, investigate, report, and recommend remediation for potential, emerging, and active security threats or incidents., • Participate in regular security risk assessments., • Evaluate software products and services to identify risks and recommend mitigation strategies for both internal and third-party technologies., • Work with staff to assess security risks in current and proposed projects., • Participate in system testing prior to production deployment to identify and resolve security-related issues., • Assist system owners and business teams in defining and applying appropriate security controls and permissions., • Investigate suspicious activities, correlate and validate alerts, coordinate response activities with management, and document all findings., • Implement approved changes and improvements to the security infrastructure, including patches, updates, reports, and alert tuning., • Monitor and report on compliance with information security policies and procedures., • Maintain required security documentation., • Conduct regular security awareness training and phishing simulations; analyze outcomes and recommend corrective actions., • Collaborate with management and vendors to recommend, implement, and improve information security and risk management best practices., • Develop, implement, and report on automated metrics for proactive monitoring of information security functions., • Actively contribute to continuous improvement of security controls and practices., • Follow and promote industry best practices related to security and data protection., • Collaborate with external Information Security partners providing managed security services, endpoint management, and security tooling., • Support auditors and assessors by providing required evidence and developing documentation demonstrating compliance with DHIN policies and procedures., • Complete project-related tasks on time and within budget., • Present security information to the workforce and management., • Bachelor’s degree in Computer Science, Information Technology, or a related field, preferred. Equivalent work experience will be considered., • 5-7 years of experience in Information Security and/or Information Technology, including vulnerability management solutions, endpoint protection applications and processes (preferably Microsoft Defender), Intrusion Prevention Systems (IPS), firewalls, web/email filtering, Data Loss Prevention (DLP), Security Incident and Event Management (SIEM), Mobile Device Management (MDM), and virtualization platforms, phishing management/simulation applications, IT training platforms, and other information security tools., • 5-7 years of experience developing, communicating, and presenting Information Security concepts to varying audiences., • Understanding of the fundamentals of IT systems, networks, and operations, including but not limited to cloud-based systems such as Amazon AWS, required., • Understanding of information security frameworks and compliance requirements, such as HITRUST CSF, CIS Top 20, HIPAA, and NIST CSF/800-53., • Able to discuss issues at technical and business levels with audiences of various backgrounds., • Ability to draw conclusions, define problems, and recommend solutions., • Ability to focus and manage time in a fast-paced, deadline-driven environment., • A security mindset able to identify, assess, quantify, and mitigate risks of all types., • Flexible and adaptable to changing circumstances., • Strong work ethic and ability to work well within a team., • Excellent verbal and written communication skills., • The base salary range for this role is $113,704 to $129,352, depending on experience and credentials. There is potential for an 8% performance incentive annually based on performance against established organizational and personal goals for each fiscal year. If the full incentive is earned, the total cash compensation for this position ranges from $122,800 to $139,700., • 22 days of paid time off annually and 13 paid holidays., • Highmark medical plan with employer contributions of 80% of the in-network deductible contributed to an HSA account of employee’s choice., • Highmark Blue Edge Dental Flex dental plan with 100% of the cost of the employee covered by DHIN (employee bears cost of dependents)., • Voluntary vision plan offerings through VSP., • Wellness programs through Blue365, Spring Health, and Well360., • SIMPLE IRA with company matching up to 4.5%., • Short- and long-term disability and AD&D insurance covered 100% by DHIN., • $50k life insurance coverage with option to increase to $100k or $150k., • Elective benefit options such as identify theft protection insurance, Accident, Critical Illness, and enhanced life insurance are available through AFLAC.Company DescriptionThe Delaware Health Information Network (DHIN) is the nation’s first statewide health information exchange. Established by statute as a not-for-profit public instrumentality, DHIN’s statutory mission is to facilitate the design and implementation of an integrated, statewide health data system to support the information needs of consumers, health plans, policymakers, providers, purchasers, and researchers to improve the quality and efficiency of health care services in Delaware. DHIN thus serves as an aggregator of health data from disparate sources and provides services to make that data useful in a variety of settings and to a variety of users. DHIN has collected and aggregated clinical data since 2007, and additionally administers Delaware’s All Payer Claims Database, with claims data from 2013 forward. Participation in DHIN by the health care community of Delaware is nearly universal, with expansion beyond state borders now also established.The Delaware Health Information Network (DHIN) is the nation’s first statewide health information exchange. Established by statute as a not-for-profit public instrumentality, DHIN’s statutory mission is to facilitate the design and implementation of an integrated, statewide health data system to support the information needs of consumers, health plans, policymakers, providers, purchasers, and researchers to improve the quality and efficiency of health care services in Delaware. DHIN thus serves as an aggregator of health data from disparate sources and provides services to make that data useful in a variety of settings and to a variety of users. DHIN has collected and aggregated clinical data since 2007, and additionally administers Delaware’s All Payer Claims Database, with claims data from 2013 forward. Participation in DHIN by the health care community of Delaware is nearly universal, with expansion beyond state borders now also established.